Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Ryan LaSalle, CEO, Nisos
For years, insider threat programs have been seeking to discern normal from anomalous behavior, minimize data loss, and protect their IP and their operations from the nightmare scenario of a trusted employee with access and an axe to grind. But heading into 2026, organizations are experiencing a fundamental shift in how trust is built, measured, and maintained. At the same time, the boundary between external and internal threats has become far more porous than most security teams are prepared to handle. The old model of looking for anomalies inside the organization is showing cracks.
The result? Insider threat is on track to become one of the defining risk challenges of 2026, not because the threat is new, but because the conditions that accelerate it are converging.
A Growing Trust Gap Will Fuel Insider Activity
One of the most disruptive forces in 2026 will be the erosion of trust within the workforce. The explosion of AI-driven job applications, identity spoofing, and synthetic profiles will continue to blur the line between legitimate and fraudulent candidates. As organizations struggle to authenticate who is entering their systems, employees themselves are becoming increasingly aware of this uncertainty.
In parallel, economic pressure, political polarization, remote-work, and increased financial stress have created fertile ground for disillusionment. Some employees – especially those feeling undervalued or insecure – or who are facing serious financial issues outside of work – may see opportunities to sell access, share credentials, or leak intellectual property.
If organizations don’t start to take a stronger approach to validating trust, insider threats will increase, both from those already inside an organization and from those who gained access through deceptive means.
Organizations Will Look Beyond the Network
Traditional insider threat programs overwhelmingly rely on internal observations: permission misuse, anomalous access, and exfiltration patterns. These signals still matter, but they aren’t enough by themselves. By the time an anomaly like this occurs, the underlying grievance or pressure has often been building within an employee for months.
In 2026, leading programs will need to expand their focus to identify early-stage red flags from outside the network. Public activity, lifestyle changes, emerging grievances, shifts in social context, and external pressures often appear in digital life long before a technical anomaly in the enterprise might. These early signals are, of course, not definitive proof of malicious intent – but they do provide essential context that can help organizations identify a possible issue and intervene before risk has a chance to escalate. Insider threat can no longer be looked at as a narrow IT problem; it has to be a part of a comprehensive overview of an organization’s human risk.
Cross-Functional Ownership Will Become the Standard
Insider threat programs that live exclusively within security or IT will struggle to keep up with the complexity of today’s human risk landscape. Legal, HR, compliance, and security each see different facets of employee behavior, and when visibility is fragmented, early signals are almost always missed.
As organizations expand visibility, they will inevitably collect more ambiguous indicators. Without skilled interpretation, teams risk treating benign signals as red flags – or worse, dismissing meaningful ones. This is why collaboration is so important.
In 2026, mature organizations will move toward shared ownership models. Some will create centralized risk committees; others will embed liaisons across HR and compliance who surfacing relevant context before issues escalate. The specific structure matters less than consistent visibility, the willingness to collaborate, and the creation of clear escalation pathways. The more siloed the program, the more likely it is to react too late.
Continuous Monitoring Will Replace Periodic Reviews
Many organizations still rely on quarterly or annual reviews, even for high-risk roles. But given the pace at which personal circumstances can shift – financial hardship, legal troubles, coercion, reputational pressure, etc. – there needs to be continuous, context-aware monitoring to gain an accurate view of risk. It should become the baseline expectation, particularly for roles with access to sensitive data, critical systems, or proprietary research.
However, this does not mean increasing invasive internal surveillance. No one wants to work for Big Brother. There has to be a defensible balance between security and employee trust. Continuous monitoring of publicly available signals can surface early red flags that traditional systems miss.
Clear policies describing what data is monitored, how it is used, and how privacy is protected help build trust and reduce organizational friction. When employees understand that programs focus on risk – not personal behavior – acceptance improves dramatically.
Preparing for 2026 and Beyond
Insider threats are not going away. If anything, the combination of workforce transformation, remote work, economic volatility, and digital anonymity is accelerating it. Organizations that embrace external-context visibility, continuous monitoring, and cross-functional collaboration will be well positioned to identify and mitigate emerging red flags before they become full-blown, organization-wide issues.
##
ABOUT THE AUTHOR
As the CEO of Nisos, the Managed Intelligence Company, Ryan LaSalle leads a mission-driven team who helps clients use the power of open source intelligence to unmask the digital threats and identify the real-world people seeking to do them harm. Ryan served as the North America Lead for Accenture Security, nurturing the talented teams that bring transformative solutions to better defend and protect clients. During more than 25 years with Accenture, Ryan led client engagements across commercial, non-profit and the public sector by integrating emerging technologies into advanced solutions to drive agility and meet business needs. A widely recognized thought leader, Ryan is a Ponemon Institute Fellow, active with the Greater Washington Board of Trade and sat on security innovation advisory councils for clients across multiple industries. He holds patents in human resource management, knowledge discovery and establishing trust between entities online. Ryan is a frequent speaker at international security conferences and has authored numerous articles on cybersecurity. He holds a Bachelor of Science degree in electrical engineering from Princeton University and lives in Alexandria, VA with his wife Melissa, their two kids, and pandemic puppy.





